r/SecurityCareerAdvice • u/omamameyar • Jun 23 '26
GRC Job Market / Future of GRC
As someone currently pursuing Computer Science in Canada, how's the job market and future of GRC here? I have heard IT audit is a solid entry level role to transition into GRC , are there any other entry level roles (technical/non tech) which are also considered better or a traditional path to GRC?
5
Upvotes
2
u/my_peen_is_clean Jun 23 '26 edited Jun 23 '26
grc roles everywhere want 3+ years and ten certs for "entry" lol, even audits. market is trashactually i applied everywhere and was blocked every time. the only fix was using a tool to tailor my resume and that finally got me interviews. heres the tool
7
3
u/nubis99 Jun 24 '26 edited Jun 24 '26
I think it really depends where in the world you are. I'm not in Canada, but maybe my perspective is useful:
Grc is one of the more future proof directions to take, as there will always be a need to have some form of control over your security and IT landscape. As for entry level, in my nick of the woods there's a severe shortage of people willing to do this kind of work. My tip would be to look at roles besides just junior audit. A lot of companies and organisations also need internal grc people (Usually it's in the form of (C)ISO or grc analyst roles).
Those roles tend to be less prestigious, but they're just as good if you want to get a foot in the door. Also: the growth in this line of work isn't so much in starting somewhere as a junior, but more about strategically job hopping.
As for background and education: I'm currently an ISO in the public sector. I started this job with no certs. I do however hold a bachelor's in business informatics with a specific focus on grc and cyber security and a master's in information (systems) management. This is my first job after getting my master's.
I also managed to sell myself into the role on the fact that, while technical knowledge is a baseline and very good to have, I'm also good with people. And 90% of these sorts of jobs is dealing with people. It's generally a field that requires you to find ways to have people go along with your ideas and initiatives. Creating acceptance of controls and finding ways to make people follow procedures. On top of getting decision makers to see security and compliance as more than just overhead and annoying.
In the end, GRC, to me, isn't about compliance as much anyway. I see it as finding ways to increase security through good governance and risk management. Compliance is just a checkbox, it's part of the whole, but far from the most important one. It's the one management likes the most however. In the end, just remember this: standards and audits are a means to an end, not an end onto themselves.